Facebook Google Plus Twitter LinkedIn YouTube RSS 功能表 搜尋 Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Advantech WebAccess < 7.0-2011.12.20 Multiple Vulnerabilities

High

Synopsis

The detected version of Advantech WebAccess may be affected by multiple attack vectors.

Description

The installed version of Advantech WebAccess is prior to 7.0-2011.12.20 and is affected by the following vulnerabilities :

- A flaw exists that allows a cross-site scripting (XSS) attack.This flaw exists because the program does not validate unspecified input before returning it to users.This may allow a remote attacker to create a specially crafted request that would execute arbitrary script code in a user's browser session within the trust relationship between their browser and the server.(OSVDB 124949) - Multiple flaws exist that may allow carrying out SQL injection attacks as unspecified input is not properly sanitized.This may allow a remote attacker to inject or manipulate SQL queries in the back-end database, allowing for the manipulation or disclosure of arbitrary data.(OSVDB 124950)

解決方案

Upgrade to Advantech WebAccess version 7.0-2011.12.20 or later.